PKCS#7 / P7B Inspector
Inspect PKCS#7 and CMS SignedData containers, list embedded certificates, signer information, algorithms, fingerprints, and certificate metadata.
PKCS#7 / CMS input
Paste a PEM container or upload a PKCS#7/CMS file. For detached signatures, also upload the exact original signed content.
PKCS#7 / CMS container
No file selected
Detached signed content (optional)
No file selected
Certificate containers
Inspect PKCS#7 and CMS SignedData structures
PKCS#7 (P7B) and CMS SignedData containers are commonly used to transport certificate chains and digital signatures without exposing private keys.
What this tool inspects
Review embedded certificates, signer information, digest and signature algorithms, certificate fingerprints, issuer and subject details, and SignedData metadata contained within PKCS#7 files.
What PKCS#7 does not contain
PKCS#7 certificate bundles typically contain public certificates only. Private keys are stored separately and should never be distributed together with a certificate chain.
Guide
About PKCS#7 and P7B Inspector
PKCS#7 and CMS SignedData containers can carry certificate chains, signer metadata, and optional signed content.
This inspector lists embedded certificates and available signer and algorithm information.
PKCS#7 certificate bundles normally do not contain private keys.
What the inspector displays
Available details depend on the SignedData structure.
- Embedded certificates
- SignerInfo entries
- Digest algorithms
- Signature algorithms
- Issuer and subject details
- Certificate fingerprints
P7B certificate bundles
P7B files are often used to distribute an end-entity certificate and intermediate chain without a private key.
CMS SignedData
CMS is the broader standard derived from PKCS#7 and can include signed content and signer attributes.
Verification limitations
Inspection does not necessarily validate signer trust, signed-content semantics, revocation, or certificate policy.
FAQ
Frequently asked questions
Does a P7B file contain a private key?
Normally no. It generally contains certificates and SignedData metadata.
What is CMS SignedData?
It is a Cryptographic Message Syntax structure for signed content and related certificates.
Can PKCS#7 contain multiple certificates?
Yes. Certificate chains are commonly bundled together.
Can I convert P7B certificates to PEM?
Individual embedded certificates can be exported or represented as PEM.
Does inspection verify the signer?
Not necessarily. Full verification requires content, signatures, chains, trust, and policy checks.
Is the container uploaded?
Inspection is intended to occur locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
PKCS#12 / PFX Inspector
Inspect certificates, private-key bags, friendly names, and identifiers inside PKCS#12 files.
PKI & Certificates
PEM Bundle Inspector
Inspect mixed PEM bundles and identify certificates, keys, CSRs, CRLs, and PKCS#7/CMS blocks.
PKI & Certificates
X.509 Certificate Decoder
Decode certificate identity, validity, algorithms, key details, and fingerprints locally.
PKI & Certificates
Certificate Chain Builder
Order X.509 certificates and generate fullchain.pem and chain.pem locally.
PKI & Certificates
CSR Decoder
Decode PKCS#10 certificate signing requests and review requested identities, keys, and extensions.
PKI & Certificates
Public & Private Key Analyzer
Identify PEM and OpenSSH key algorithms, formats, sizes, curves, and fingerprints locally.
PKI & Certificates